Executive Summary



This Alert is flagged as TOP 25 Common Weakness Enumeration from CWE/SANS. For more information, you can read this.
Summary
Title New gforge packages fix insufficient input sanitising
Informations
Name DSA-1818 First vendor Publication 2009-06-18
Vendor Debian Last vendor Modification 2009-06-18
Severity (Vendor) N/A Revision 1

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:P/I:P/A:P)
Cvss Base Score 7.5 Attack Range Network
Cvss Impact Score 6.4 Attack Complexity Low
Cvss Expoit Score 10 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Laurent Almeras and Guillaume Smet have discovered a possible SQL injection vulnerability and cross-site scripting vulnerabilities in gforge, a collaborative development tool. Due to insufficient input sanitising, it was possible to inject arbitrary SQL statements and use several parameters to conduct cross-site scripting attacks.

For the stable distribution (lenny), these problem have been fixed in version 4.7~rc2-7lenny1.

The oldstable distribution (etch), these problems have been fixed in version 4.5.14-22etch11.

For the testing distribution (squeeze), these problems will be fixed soon.

For the unstable distribution (sid), these problems have been fixed in version 4.7.3-2.

We recommend that you upgrade your gforge packages.

Original Source

Url : http://www.debian.org/security/2009/dsa-1818

CWE : Common Weakness Enumeration

% Id Name
50 % CWE-89 Improper Sanitization of Special Elements used in an SQL Command ('SQL Injection') (CWE/SANS Top 25)
50 % CWE-79 Failure to Preserve Web Page Structure ('Cross-site Scripting') (CWE/SANS Top 25)

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 2

OpenVAS Exploits

Date Description
2009-06-23 Name : Debian Security Advisory DSA 1818-1 (gforge)
File : nvt/deb_1818_1.nasl

Open Source Vulnerability Database (OSVDB)

Id Description
56234 GForge Unspecified XSS

GForge contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate unspecified parameters upon submission to unspecified script(s). This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
56233 GForge Unspecified SQL Injection

GForge contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to unspecified functionality not properly sanitizing unspecified user-supplied input. This may allow an attacker to inject or manipulate SQL queries in the back-end database.

Nessus® Vulnerability Scanner

Date Description
2009-06-18 Name : The remote Debian host is missing a security-related update.
File : debian_DSA-1818.nasl - Type : ACT_GATHER_INFO
2007-10-08 Name : The remote web server contains a PHP script that is affected by a cross-site ...
File : gforge_confirm_hash_xss.nasl - Type : ACT_ATTACK

Alert History

If you want to see full details history, please login or register.
0
Date Informations
2014-02-17 11:28:33
  • Multiple Updates